Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

101–110 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#101

What is so hard to maintain an already finished Electron app?

I can imagine a scenario where it needs dependency updates, engineers bring this up, bean counters say “well this doesn’t make us money, spend time on things that make us money instead” until eventually the bean counters say “okay we are no longer doing this, shut it down”

More likely they want to get mobile data from desktop users. Probably with a plan to monetize it somehow later.

Re: End of Life for Twilio Authy Desktop App

#102
post #99
post #8

Earlier quoted context omitted.

> not sure how I feel about passwords and totp being in the same app I felt the same way and I've come to realize that it is not a big deal. One advantage is that with a shared password manager account, you can also share the TOTP along with it. Very convenient for a bunch of usecases.

Is it really multifactor then, with everything in Bitwarden?

The way I see it, your password manager becomes the central point of failure. Therefore, secure your password manager with a hardware security key (yubi). Not all accounts stored in a password manager are created equal... some need more security than others. If there are accounts that you want additional 2FA security on, just use a separate TOTP app. It doesn't have to be an all or none option.

Re: End of Life for Twilio Authy Desktop App

#103
post #70

Earlier quoted context omitted.

Of course, if you have an Apple product, you can also use the TOTP function built-in to Keychain. iPhone doc here: https://support.apple.com/guide/iphone/automatically-fill-in...

The downside to this, is that you're tied into Apple's ecosystem. The nice thing about Authy was that I had the same access on Android, iOS, Windows, Mac, and Linux.

Apple makes an app for accessing passwords on Windows, but I would not put a lot of faith in them supporting it forever, as Twilio has reminded us.

https://support.apple.com/guide/icloud-windows/set-up-icloud...

Re: End of Life for Twilio Authy Desktop App

#105
post #21
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

What should I replace it with? Any recommendations for a functionally equivalent cross-device 2FA app?

The easiest thing to do is set up a 2FA mule.

Re: End of Life for Twilio Authy Desktop App

#106
post #60
post #45

As someone who just uses good old passwords managed with TXT files and sticky notes: Security engineers (marketers?) never seem to understand most people by far value convenience over security.

You're gonna get pwned, and you're gonna get pwned hard. Brace for it because it's coming sooner or later. It's convenient until you lose all of your passwords.

The point still needs to be made.

I always present security as a sliding scale with secure on one side and convenient on the other. Similar to low-cost and convenient streaming services reducing piracy, and then seeing the return of piracy as they become higher cost and less-convenient, any application needs to consider not only how to protect its users and their data, but also how to not drive away users with security measures that encroach into that inconvenient zone.

2FA can definitely approach that zone in a few different ways eg. having to reauthenticate too often, or especially for technical users in situations where account sharing is a reality that isn't going away anytime soon: by not making your secret tokens readily available. It has been evident for years that Twilio was just trying to force vendor lock-in and I've always hated Authy. The desktop app at least gave you some agency (secrets on a device that you own and fully control), but I guess that was too much too ask in the long term.

Aside: there are measures that increase security without affecting convenience (much). Take those first.

Additional Aside to the text file password cowboy: since moving into password managers (first lastpass, now bitwarden) I've found it to be more convenient (usually) and I have a lot more peace of mind about it. Maybe try it?

Re: End of Life for Twilio Authy Desktop App

#107
post #14

Earlier quoted context omitted.

And they try to lock you in to their own ecosystem. If you use sendgrid, it requires an authy specific 2fa code that can only be generated in their app.

Yeah. I have always wondered what they gain by doing this.

Lock-in by forcing you to use another Twilio product.

Re: End of Life for Twilio Authy Desktop App

#108
post #21
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

What should I replace it with? Any recommendations for a functionally equivalent cross-device 2FA app?

[deleted]

Re: End of Life for Twilio Authy Desktop App

#109

This was literally the only reason to use Authy.

Maybe not the only reason, but this was definitely one of the main reasons I used Authy. Over time, the product has been getting progressively worse... When I first started using it there was a Chrome App you could install which was great because it could work on "corporate" machines where I wasn't able to install the desktop app. That went away a long time ago, but at least we had the desktop app on Windows, Mac, Linux. Although, at some point Authy was only available on Linux if using Snap, which ruled it out for me (although there is an unofficial Flatpak now). So now they are getting rid of all desktop apps which will be the end of my Authy journey and this will also be the last Twilio product I use, since I've had recent bad experiences with some of their other products.

Re: End of Life for Twilio Authy Desktop App

#110
post #38

Earlier quoted context omitted.

I use Authy. I've read a few comments about how migrating away is difficult. What do you use instead? I also use bitwarden, but not sure how I feel about passwords and totp being in the same app.

> I also use bitwarden, but not sure how I feel about passwords and totp being in the same app. I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure? If someone gets access to your unlocked PC/phone, don't they then have access to both? Do you store your TOTP vault password in your password vault (obvious)? If someone gets into your pas…

I use iCloud Keychain because I use a Mac, iPad, and iPhone.

I use Authy with Face ID protecting the entire app on my phone. I don't use the Desktop app because it won't use Touch ID, meaning I have to type in a long master password.

I don't see an attack as likely to happen (I own no Bitcoin, not a billionaire, not in charge of anyone else's secrets) but if there was a flaw that let somebody access the passwords on my Mac or iPhone, they'd still need the 2FA codes from my phone. I think that's more likely to happen on the Mac because I do have apps downloaded from somewhere else besides Apple's App Store.

My guess is that most of the people who worked on Authy have fallen by the wayside after the Twilio acquisition. It's annoying every time I have to search the boxes on my phone or the list on my watch: can't we please have alphabetization?

Post reply on HN